well here i am again. last time i was here, i couldn't understand ANYTHING i was told to do, so i just quit. but now i think i'm infected and can't quit so please try to understand how stoooopid i am and that every little step has to be explained… like just now, don't ask me how i screwed up, but it didn't ask me to download to the desktop and it didn't so i hope i can find the logs and post them here
Ran by [removed] (administrator) on DESKTOP-A128AVT (Dell Inc. Inspiron 5537) (17-02-2021 20:13:35)
[removed]
Platform: Windows 10 Home Version 2004 19041.746 (X64) Language: English (United States)
Default browser: "C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe" –single-argument %1
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe <4>
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe <21>
(AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\1.8.1066.0\AVGBrowserCrashHandler.exe
(AVG Technologies USA, LLC -> AVG Technologies) C:\Program Files (x86)\AVG\Browser\Update\1.8.1066.0\AVGBrowserCrashHandler64.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <4>
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-03] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-03] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [116960 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-45112709-2347109901-132268321-1001\…\Run: [ShowBatteryBar] => C:\Program Files\BatteryBar\ShowBatteryBar.exe [89600 2014-09-19] () [File not signed]
HKU\S-1-5-21-45112709-2347109901-132268321-1001\…\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [32440376 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-45112709-2347109901-132268321-1001\…\MountPoints2: {e2539d6c-ba5e-11ea-aeb7-806e6f6e6963} - "E:\Autorun.exe"
HKLM\Software\Microsoft\Active Setup\Installed Components: [{48F69C39-1356-4A7B-A899-70E3539D4982}] -> C:\Program Files (x86)\AVG\Browser\Application\88.0.7977.152\Installer\chrmstp.exe [2021-02-10] (AVG Technologies USA, LLC -> AVG Technologies)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08754BB9-A111-44F9-A476-7B992287E957} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [677344 2021-02-08] (Mozilla Corporation -> Mozilla Foundation)
Task: {10514CA0-ABFF-47FE-85DF-0B633E1D35E9} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4682976 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
Task: {295879EB-2C81-439E-B3E2-F89123C57E40} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-03] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {2CA4712D-95C6-43CE-AC76-07DCBDA67ED8} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1741416 2021-02-17] (Avast Software s.r.o. -> Avast Software)
Task: {3FD7FEB1-92E9-4AAB-BCD5-E97AA669956E} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1706496 2020-06-25] () [File not signed]
Task: {5F8D2346-E66B-4467-B194-409939870EFA} - System32\Tasks\AVGUpdateTaskMachineUA => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-11-04] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {836A11FC-D1FC-42C0-A3FC-3DE5DD12BC0D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {ACCFCC2D-303C-45D3-9D4E-98A179ABA8D2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [26913848 2021-01-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {B332DB87-9371-4994-9475-DFB37CF3133B} - System32\Tasks\AVG Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [2196032 2021-02-05] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {C58171CA-5FA6-4C9C-B1EF-88B5786DBD23} - System32\Tasks\AVG Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe [2196032 2021-02-05] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {EF86120B-EF6C-41D6-A775-71C53DC68012} - System32\Tasks\AVGUpdateTaskMachineCore => C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-11-04] (AVG Technologies USA, LLC -> AVG Technologies)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{385eae30-3a8a-42a2-bcfd-88e1dd7261b4}: [DhcpNameServer] 192.168.1.254
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2021-02-17]
FireFox:
========
FF DefaultProfile: kehed5pg.default
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kehed5pg.default [2020-07-03]
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kbauobpn.default-release-1613588670257 [2021-02-17]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=3 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1066.0\npAvgBrowserUpdate3.dll [2020-11-04] (AVG Technologies USA, LLC -> AVG Technologies)
FF Plugin-x32: @update.avgbrowser.com/AVG Browser;version=9 -> C:\Program Files (x86)\AVG\Browser\Update\1.8.1066.0\npAvgBrowserUpdate3.dll [2020-11-04] (AVG Technologies USA, LLC -> AVG Technologies)
Chrome:
=======
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2021-02-17]
CHR Extension: (Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-06-29]
CHR Extension: (Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-06-29]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-06-29]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-06-29]
CHR Extension: (uBlock Origin) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-06-29]
CHR Extension: (Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-06-29]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-06-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-06-29]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-06-29]
CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-06-29]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [7878680 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [621608 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [352480 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56904 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
S2 avg; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-11-04] (AVG Technologies USA, LLC -> AVG Technologies)
S3 avgm; C:\Program Files (x86)\AVG\Browser\Update\AVGBrowserUpdate.exe [201984 2020-11-04] (AVG Technologies USA, LLC -> AVG Technologies)
S3 AVGSecureBrowserElevationService; C:\Program Files (x86)\AVG\Browser\Application\88.0.7977.152\elevation_service.exe [1455344 2021-02-05] (AVG Technologies USA, LLC -> AVG Technologies)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2101.9-0\NisSrv.exe [2462960 2021-02-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2101.9-0\MsMpEng.exe [128376 2021-02-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 uhssvc; "C:\Program Files\Microsoft Update Health Tools\uhssvc.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [35648 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [208024 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [357320 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [249304 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [98760 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
S0 aswElam; C:\Windows\System32\drivers\aswElam.sys [16832 2021-02-17] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [41272 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [175240 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [521336 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [107784 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [83360 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [850112 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [466224 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [215328 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [326976 2021-02-17] (Avast Software s.r.o. -> AVAST Software)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [29160 2018-07-27] (Dell Inc -> OSR Open Systems Resources, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [49552 2021-02-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [419040 2021-02-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [71912 2021-02-12] (Microsoft Windows -> Microsoft Corporation)
S3 MpKsla7f15af6; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ABCF8BD8-04BF-42B5-AFD7-2A7E55013BD8}\MpKslDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-02-17 20:13 - 2021-02-17 20:15 - 000015216 _____ C:\Users\User\Downloads\FRST.txt
2021-02-17 20:12 - 2021-02-17 20:14 - 000000000 ____D C:\FRST
2021-02-17 20:11 - 2021-02-17 20:11 - 002298368 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2021-02-17 20:10 - 2021-02-17 20:10 - 002011136 _____ (Farbar) C:\Users\User\Downloads\FRST.exe
2021-02-17 15:39 - 2021-02-17 15:39 - 000002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2021-02-17 15:39 - 2021-02-17 15:39 - 000002144 _____ C:\ProgramData\Desktop\Avast Free Antivirus.lnk
2021-02-17 15:39 - 2021-02-17 15:39 - 000000000 ____D C:\Users\User\AppData\Roaming\Avast Software
2021-02-17 15:39 - 2021-02-17 15:39 - 000000000 ____D C:\Users\User\AppData\Local\CEF
2021-02-17 15:38 - 2021-02-17 15:38 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2021-02-17 15:37 - 2021-02-17 15:37 - 000521336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetHub.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000466224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000339680 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2021-02-17 15:37 - 2021-02-17 15:37 - 000326976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000249304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000215328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000175240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000107784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000098760 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000083360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000041272 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000016832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswElam.sys
2021-02-17 15:37 - 2021-02-17 15:37 - 000003990 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2021-02-17 15:37 - 2021-02-17 15:37 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2021-02-17 15:37 - 2021-02-17 15:36 - 000850112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2021-02-17 15:37 - 2021-02-17 15:36 - 000357320 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2021-02-17 15:37 - 2021-02-17 15:36 - 000208024 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2021-02-17 15:37 - 2021-02-17 15:36 - 000035648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2021-02-17 15:36 - 2021-02-17 15:36 - 000000000 ____D C:\Program Files\Avast Software
2021-02-17 15:35 - 2021-02-17 15:39 - 000000000 ____D C:\ProgramData\Avast Software
2021-02-17 15:35 - 2021-02-17 15:35 - 000220392 _____ (AVAST Software) C:\Users\User\Downloads\avast_free_antivirus_setup_online.exe
2021-02-17 15:35 - 2021-02-17 15:35 - 000220392 _____ (AVAST Software) C:\Users\User\Downloads\avast_free_antivirus_setup_online (1).exe
2021-02-17 14:04 - 2021-02-17 14:04 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-02-17 14:04 - 2021-02-17 14:04 - 000000993 _____ C:\ProgramData\Desktop\Firefox.lnk
2021-02-17 14:04 - 2021-02-17 14:04 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2021-02-17 14:04 - 2021-02-17 14:04 - 000000000 ____D C:\Users\User\Desktop\Old Firefox Data
2021-02-17 14:04 - 2021-02-17 14:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-02-17 14:04 - 2021-02-17 14:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-02-17 14:03 - 2021-02-17 14:03 - 000333040 _____ (Mozilla) C:\Users\User\Downloads\Firefox Installer.exe
2021-02-16 03:26 - 2021-02-16 03:26 - 000746504 _____ C:\Users\User\Downloads\210216-1392098237.exe
2021-02-14 23:51 - 2021-02-14 23:56 - 000002506 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-02-09 02:26 - 2021-02-09 02:26 - 000639314 _____ C:\Users\User\Downloads\210208-holodook-j.jg6
2021-02-09 02:26 - 2021-02-09 02:26 - 000639314 _____ C:\Users\User\Downloads\210208-holodook-j (1).jg6
2021-02-02 08:10 - 2021-02-02 08:10 - 000467361 _____ C:\Users\User\Downloads\210201-1496204615.jg6
2021-02-02 08:10 - 2021-02-02 08:10 - 000467361 _____ C:\Users\User\Downloads\210201-1496204615 (1).jg6
2021-01-28 20:44 - 2021-01-28 20:44 - 000968492 _____ C:\Users\User\Downloads\Hi everyone — Nextdoor.html
2021-01-28 20:44 - 2021-01-28 20:44 - 000000000 ____D C:\Users\User\Downloads\Hi everyone — Nextdoor_files
2021-01-26 16:07 - 2021-01-26 16:07 - 000418863 _____ C:\Users\User\Downloads\210125-diehl-l.jg6
2021-01-24 16:27 - 2021-02-14 23:48 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-01-18 09:20 - 2021-01-18 09:20 - 000581120 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2021-01-18 09:20 - 2021-01-18 09:20 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
2021-01-18 09:20 - 2021-01-18 09:20 - 000234496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
2021-01-18 09:20 - 2021-01-18 09:20 - 000204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2021-01-18 09:20 - 2021-01-18 09:20 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VBICodec.ax
2021-01-18 09:20 - 2021-01-18 09:20 - 000095744 _____ C:\Windows\system32\VirtualMonitorManager.dll
2021-01-18 09:20 - 2021-01-18 09:20 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2021-01-18 09:19 - 2021-01-18 09:19 - 002755584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2021-01-18 09:19 - 2021-01-18 09:19 - 002755584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2021-01-18 09:19 - 2021-01-18 09:19 - 000729600 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2021-01-18 09:19 - 2021-01-18 09:19 - 000575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hhctrl.ocx
2021-01-18 09:19 - 2021-01-18 09:19 - 000469504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
2021-01-18 09:19 - 2021-01-18 09:19 - 000304128 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2021-01-18 09:19 - 2021-01-18 09:19 - 000266240 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2021-01-18 09:19 - 2021-01-18 09:19 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2021-01-18 09:19 - 2021-01-18 09:19 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2021-01-18 09:19 - 2021-01-18 09:19 - 000084992 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2021-01-18 09:19 - 2021-01-18 09:19 - 000072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2021-01-18 09:19 - 2021-01-18 09:19 - 000053760 _____ C:\Windows\SysWOW64\BWContextHandler.dll
2021-01-18 09:19 - 2021-01-18 09:19 - 000045880 _____ C:\Windows\system32\HvSocket.dll
2021-01-18 09:18 - 2021-01-18 09:18 - 001309504 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2021-01-18 09:18 - 2021-01-18 09:18 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2021-01-18 09:18 - 2021-01-18 09:18 - 000446976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmsys.cpl
2021-01-18 09:18 - 2021-01-18 09:18 - 000221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
2021-01-18 09:18 - 2021-01-18 09:18 - 000178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2021-01-18 09:18 - 2021-01-18 09:18 - 000112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\activeds.tlb
2021-01-18 09:18 - 2021-01-18 09:18 - 000100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncpa.cpl
2021-01-18 09:18 - 2021-01-18 09:18 - 000067072 _____ C:\Windows\system32\BWContextHandler.dll
2021-01-18 09:18 - 2021-01-18 09:18 - 000047472 _____ C:\Windows\SysWOW64\umpdc.dll
2021-01-18 09:18 - 2021-01-18 09:18 - 000039936 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2021-01-18 09:18 - 2021-01-18 09:18 - 000010894 _____ C:\Windows\system32\DrtmAuthTxt.wim
2021-01-18 09:17 - 2021-01-18 09:17 - 001333760 _____ C:\Windows\SysWOW64\TextInputMethodFormatter.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 001162240 _____ C:\Windows\system32\MBR2GPT.EXE
2021-01-18 09:17 - 2021-01-18 09:17 - 000611952 _____ C:\Windows\SysWOW64\TextShaping.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 000455680 _____ C:\Windows\SysWOW64\WindowManagementAPI.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 000422912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2021-01-18 09:17 - 2021-01-18 09:17 - 000330752 _____ C:\Windows\SysWOW64\ssdm.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 000266240 _____ C:\Windows\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 000240640 _____ C:\Windows\SysWOW64\CoreMas.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 000235520 _____ C:\Windows\SysWOW64\HeatCore.dll
2021-01-18 09:17 - 2021-01-18 09:17 - 000182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2021-01-18 09:17 - 2021-01-18 09:17 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msacm32.drv
2021-01-18 09:17 - 2021-01-18 09:17 - 000010752 _____ C:\Windows\SysWOW64\agentactivationruntimestarter.exe
2021-01-18 09:16 - 2021-01-18 09:16 - 002254336 _____ C:\Windows\system32\dwmscene.dll
2021-01-18 09:16 - 2021-01-18 09:16 - 001822272 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2021-01-18 09:16 - 2021-01-18 09:16 - 001393496 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2021-01-18 09:16 - 2021-01-18 09:16 - 000544768 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2021-01-18 09:16 - 2021-01-18 09:16 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2021-01-18 09:16 - 2021-01-18 09:16 - 000238592 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2021-01-18 09:16 - 2021-01-18 09:16 - 000190976 _____ C:\Windows\system32\BthpanContextHandler.dll
2021-01-18 09:16 - 2021-01-18 09:16 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\ncpa.cpl
2021-01-18 09:16 - 2021-01-18 09:16 - 000060928 _____ C:\Windows\system32\runexehelper.exe
2021-01-18 09:16 - 2021-01-18 09:16 - 000048640 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2021-01-18 09:16 - 2021-01-18 09:16 - 000001370 _____ C:\Windows\system32\ThirdPartyNoticesBySHS.txt
2021-01-18 09:15 - 2021-01-18 09:15 - 002260992 _____ C:\Windows\system32\TextInputMethodFormatter.dll
2021-01-18 09:15 - 2021-01-18 09:15 - 002260480 _____ (The ICU Project) C:\Windows\system32\icu.dll
2021-01-18 09:15 - 2021-01-18 09:15 - 000707544 _____ C:\Windows\system32\TextShaping.dll
2021-01-18 09:15 - 2021-01-18 09:15 - 000643072 _____ C:\Windows\system32\WindowManagementAPI.dll
2021-01-18 09:15 - 2021-01-18 09:15 - 000306688 _____ C:\Windows\system32\HeatCore.dll
2021-01-18 09:15 - 2021-01-18 09:15 - 000152064 _____ C:\Windows\system32\EoAExperiences.exe
2021-01-18 09:15 - 2021-01-18 09:15 - 000112128 _____ (Microsoft Corporation) C:\Windows\system32\activeds.tlb
2021-01-18 09:15 - 2021-01-18 09:15 - 000029696 _____ (The ICU Project) C:\Windows\system32\icuuc.dll
2021-01-18 09:15 - 2021-01-18 09:15 - 000025088 _____ (The ICU Project) C:\Windows\system32\icuin.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 004227116 _____ C:\Windows\system32\DefaultHrtfs.bin
2021-01-18 09:13 - 2021-01-18 09:13 - 000562688 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2021-01-18 09:13 - 2021-01-18 09:13 - 000455168 _____ C:\Windows\system32\ssdm.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000363520 _____ C:\Windows\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000287232 _____ C:\Windows\system32\CoreMas.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2021-01-18 09:13 - 2021-01-18 09:13 - 000197632 _____ C:\Windows\system32\IHDS.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000165888 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe
2021-01-18 09:13 - 2021-01-18 09:13 - 000089088 _____ C:\Windows\system32\windows.applicationmodel.conversationalagent.proxystub.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000074240 _____ C:\Windows\system32\rdsxvmaudio.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000073216 _____ C:\Windows\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000064552 _____ C:\Windows\system32\umpdc.dll
2021-01-18 09:13 - 2021-01-18 09:13 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\msacm32.drv
2021-01-18 09:13 - 2021-01-18 09:13 - 000013312 _____ C:\Windows\system32\agentactivationruntimestarter.exe
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-02-17 20:04 - 2020-06-29 17:25 - 000795738 _____ C:\Windows\system32\PerfStringBackup.INI
2021-02-17 20:04 - 2019-12-07 04:13 - 000000000 ____D C:\Windows\INF
2021-02-17 20:00 - 2020-07-03 14:24 - 000000000 ____D C:\Program Files\CCleaner
2021-02-17 19:56 - 2020-06-29 11:19 - 000000000 ____D C:\Users\User\AppData\Local\ClassicShell
2021-02-17 19:55 - 2020-06-29 17:18 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-02-17 18:02 - 2019-12-07 04:03 - 000000000 ____D C:\Windows\CbsTemp
2021-02-17 17:35 - 2020-06-29 10:35 - 000000000 ____D C:\Windows\system32\MRT
2021-02-17 17:31 - 2020-06-29 10:35 - 130141752 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-02-17 17:22 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-02-17 15:37 - 2019-12-07 04:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2021-02-17 15:32 - 2019-12-07 04:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2021-02-17 15:32 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\AppReadiness
2021-02-17 15:31 - 2020-06-29 10:46 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2021-02-17 15:31 - 2020-06-29 10:46 - 000000000 __SHD C:\Users\User\IntelGraphicsProfiles
2021-02-17 15:25 - 2020-06-29 17:19 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-02-17 15:25 - 2020-06-29 17:18 - 000458192 _____ C:\Windows\system32\FNTCACHE.DAT
2021-02-17 15:25 - 2020-06-29 17:18 - 000008192 ___SH C:\DumpStack.log.tmp
2021-02-17 15:25 - 2019-12-07 04:03 - 001310720 _____ C:\Windows\system32\config\BBI
2021-02-17 15:23 - 2019-12-07 04:52 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-02-17 15:23 - 2019-12-07 04:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ___SD C:\Windows\SysWOW64\F12
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ___SD C:\Windows\SysWOW64\DiagSvcs
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ___SD C:\Windows\system32\UNP
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ___SD C:\Windows\system32\F12
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ___SD C:\Windows\system32\DiagSvcs
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ___RD C:\Windows\PrintDialog
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\PerceptionSimulation
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\Com
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SysWOW64\AdvancedInstallers
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\SystemResources
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\WinMetadata
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\SystemResetPlatform
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\Sysprep
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\setup
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\oobe
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\migwiz
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\inetsrv
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\es-MX
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\Dism
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\Com
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\appraiser
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\system32\AdvancedInstallers
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\ShellExperiences
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\ShellComponents
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\Provisioning
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\IME
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\DiagTrack
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\bcastdvr
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-02-17 15:23 - 2019-12-07 04:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2021-02-17 15:23 - 2019-12-07 04:03 - 000000000 ____D C:\Windows\servicing
2021-02-17 15:22 - 2020-07-03 14:14 - 000000000 ____D C:\ProgramData\Mozilla
2021-02-17 15:21 - 2020-07-03 14:14 - 000000000 ____D C:\Users\User\AppData\LocalLow\Mozilla
2021-02-17 14:36 - 2019-12-07 04:14 - 000000000 ____D C:\Windows\LiveKernelReports
2021-02-16 03:26 - 2020-07-03 15:10 - 000000000 ____D C:\Program Files (x86)\BigJig
2021-02-12 15:27 - 2020-06-29 17:19 - 000000000 ____D C:\Windows\system32\Drivers\wd
2021-02-12 15:25 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-02-11 03:44 - 2020-08-31 15:18 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-02-11 03:44 - 2020-08-31 15:18 - 000003356 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-02-10 14:17 - 2020-11-04 22:12 - 000002375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Secure Browser.lnk
2021-02-10 14:17 - 2020-11-04 22:12 - 000002340 _____ C:\ProgramData\Desktop\AVG Secure Browser.lnk
2021-01-31 21:45 - 2020-06-29 17:29 - 000000000 ____D C:\Users\User\AppData\Local\Packages
2021-01-22 08:23 - 2020-06-29 10:44 - 000799104 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2021-01-18 09:31 - 2019-12-07 04:52 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\OEMDefaultAssociations.dll
2021-01-18 09:31 - 2019-12-07 04:52 - 000020908 _____ C:\Windows\system32\OEMDefaultAssociations.xml
2021-01-18 09:13 - 2020-06-29 17:23 - 002877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt =======================
ok, that worked now i will try to do it again:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-02-2021 01
Ran by [removed] (17-02-2021 20:23:13)
Running from C:\Users\[removed]\Downloads
Windows 10 Home Version 2004 19041.746 (X64) (2020-06-29 22:21:12)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-45112709-2347109901-132268321-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-45112709-2347109901-132268321-503 - Limited - Disabled)
Guest (S-1-5-21-45112709-2347109901-132268321-501 - Limited - Disabled)
User (S-1-5-21-45112709-2347109901-132268321-1001 - Administrator - Enabled) => C:\Users\User
WDAGUtilityAccount (S-1-5-21-45112709-2347109901-132268321-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 19.00 (x64) (HKLM\…\7-Zip) (Version: 19.00 - Igor Pavlov)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 32.0.0.125 - Adobe)
AdoptOpenJDK JRE with Hotspot 11.0.7.10 (x64) (HKLM\…\{59029173-BEEB-4B56-8AAB-CB4BA00C6CCF}) (Version: 11.0.7.10 - AdoptOpenJDK)
AdoptOpenJDK JRE with Hotspot 8.0.252.09 (x64) (HKLM\…\{E652CBE7-6CBA-4767-934C-8FBFFD8DFC55}) (Version: 8.0.252.09 - AdoptOpenJDK)
AdoptOpenJDK JRE with Hotspot 8.0.252.09 (x86) (HKLM-x32\…\{8210A470-923F-43BC-B1BF-745918F41E8C}) (Version: 8.0.252.09 - AdoptOpenJDK)
Astra Gift Maker version 1.2 (HKLM-x32\…\Astra Gift Maker_is1) (Version: - )
Astra Jigsaw Art V version 1.34 (HKLM-x32\…\Astra Jigsaw Art V_is1) (Version: - )
Astra Jigsaw Asian Holidays version 1.32 (HKLM-x32\…\Astra Jigsaw Asian Holidays_is1) (Version: - )
Astra Jigsaw Britain version 1.38 (HKLM-x32\…\Astra Jigsaw Britain_is1) (Version: - )
Astra Jigsaw Islands version 1.35 (HKLM-x32\…\Astra Jigsaw Islands_is1) (Version: - )
Astra Jigsaw Scandinavia version 1.33 (HKLM-x32\…\Astra Jigsaw Scandinavia_is1) (Version: - )
Astra Jigsaw Tropical Edition version 1.32 (HKLM-x32\…\Astra Jigsaw Tropical Edition_is1) (Version: - )
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 21.1.2449 - Avast Software)
AVG Secure Browser (HKLM-x32\…\AVG Secure Browser) (Version: 88.0.7977.152 - AVG Technologies)
AVG Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.8.1066.0 - AVG Technologies) Hidden
BatteryBar (remove only) (HKLM\…\BatteryBar) (Version: - )
BigJig version 8.28 (HKLM-x32\…\BigJig_is1) (Version: - )
CCleaner (HKLM\…\CCleaner) (Version: 5.76 - Piriform)
CDBurnerXP (HKLM\…\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.8.7128 - CDBurnerXP)
Classic Shell (HKLM\…\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 19.2.17.64 - Synaptics Incorporated)
Desktop Taipei version 2.3.1 (HKLM-x32\…\Desktop Taipei_is1) (Version: - )
K-Lite Codec Pack 15.5.6 Full (HKLM-x32\…\KLiteCodecPack_is1) (Version: 15.5.6 - KLCP)
LibreOffice 6.4.4.2 (HKLM\…\{F00C391B-6092-40E7-9ECD-144933865571}) (Version: 6.4.4.2 - The Document Foundation)
Microsoft Edge (HKLM-x32\…\Microsoft Edge) (Version: 88.0.705.68 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\…\Microsoft Edge Update) (Version: 1.3.141.59 - )
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Mozilla Firefox 85.0.2 (x64 en-US) (HKLM\…\Mozilla Firefox 85.0.2 (x64 en-US)) (Version: 85.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 85.0.2 - Mozilla)
Notepad++ (32-bit x86) (HKLM-x32\…\Notepad++) (Version: 7.8.8 - Notepad++ Team)
paint.net (HKLM\…\{7ADB1B05-39DE-4888-A72D-D1F3A791D45F}) (Version: 4.2.12 - dotPDN LLC)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7544 - Realtek Semiconductor Corp.)
Packages:
=========
Hidden City: Hidden Object Adventure -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6 [2021-02-01] (G5 Entertainment AB)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-06-29] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-06-29] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.1252.0_x64__8wekyb3d8bbwe [2021-01-30] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0 [2021-02-04] (Spotify AB) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-02-17] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-02-17] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2020-06-23] (Notepad++ -> )
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-02-17] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-02-17] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2017-02-24] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-02-17] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\Windows\system32\StartMenuHelper64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2017-08-13 07:49 - 2017-08-13 07:49 - 003664184 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-45112709-2347109901-132268321-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://duckduckgo.com/
SearchScopes: HKU\S-1-5-21-45112709-2347109901-132268321-1001 -> {02A5E369-FCD7-4E88-9BD1-3E59061BCF02} URL = hxxps://duckduckgo.com/?q={searchTerms}&atb;=v248-5__
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 04:14 - 2019-12-07 04:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\AdoptOpenJDK\jre-11.0.7.10-hotspot\bin;C:\Program Files\AdoptOpenJDK\jre-8.0.252.09-hotspot\bin;C:\Program Files (x86)\AdoptOpenJDK\jre-8.0.252.09-hotspot\bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-45112709-2347109901-132268321-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\User\Pictures\gwb.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{03D87480-9E28-434E-AA77-AD6D9475C173}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C4FEA9E2-2DB1-4FAC-8A17-F92233AFE08C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{4867B080-C46D-43CE-A5B6-C9FC60B8B58F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D490B50D-D09D-46B4-A318-87283077EF8E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FB97A780-CC53-4B80-A338-DFB2A826B8E1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8246A694-A8DA-4E67-890A-1CCB37281CB1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E28AE70A-B927-4C47-BDCE-973A302947E0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{0E1C9415-0307-4C23-A832-C2AFA9A206FC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{572AB098-616A-406E-93E0-905C43CB1AB3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F676BDF4-F3CA-4122-8455-4B4354368F3C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{391C7126-C2E6-4D41-A522-0DBEFD81D04D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{225A8145-8146-4E7C-9C32-A422EA5214D4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{5E95D610-C6D3-4135-98E4-5E6AC6AE9DAC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.152.687.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D49A3340-EF1B-49F7-A0BB-161699AE65B4}] => (Allow) C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe (AVG Technologies USA, LLC -> AVG Technologies)
==================== Restore Points =========================
14-02-2021 20:14:37 Scheduled Checkpoint
17-02-2021 17:36:03 Windows Modules Installer
17-02-2021 17:38:09 Windows Modules Installer
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (02/17/2021 02:44:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program HiddenCityUWP.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 2214
Start Time: 01d705646d9ba725
Termination Time: 4294967295
Application Path: C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6\HiddenCityUWP.exe
Report Id: 52d8d325-654a-47a9-8fa4-99cceea88411
Faulting package full name: 828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6
Faulting package-relative application ID: App
Hang type: Quiesce
Error: (02/17/2021 02:44:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RtkNGUI64.exe, version: 1.0.484.0, time stamp: 0x55893580
Faulting module name: ucrtbase.dll, version: 10.0.19041.1, time stamp: 0xbd1e2564
Exception code: 0xc00000fd
Fault offset: 0x000000000000dd72
Faulting process id: 0x1eec
Faulting application start time: 0x01d6ec0ca0574a3f
Faulting application path: C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
Faulting module path: C:\Windows\System32\ucrtbase.dll
Report Id: cf288d19-df34-4800-8a4b-1a77d3c2b5fa
Faulting package full name:
Faulting package-relative application ID:
Error: (02/17/2021 02:44:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RAVBg64.exe, version: 1.0.0.220, time stamp: 0x553f3a75
Faulting module name: ucrtbase.dll, version: 10.0.19041.1, time stamp: 0xbd1e2564
Exception code: 0xc00000fd
Fault offset: 0x000000000000dd72
Faulting process id: 0xb00
Faulting application start time: 0x01d6ec0bded53a5f
Faulting application path: C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
Faulting module path: C:\Windows\System32\ucrtbase.dll
Report Id: fcdd976a-13ea-4535-a7b1-d04d309c7bff
Faulting package full name:
Faulting package-relative application ID:
Error: (02/17/2021 02:44:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SynTPEnh.exe, version: 19.2.17.64, time stamp: 0x5a35d26a
Faulting module name: ucrtbase.dll, version: 10.0.19041.1, time stamp: 0xbd1e2564
Exception code: 0xc00000fd
Fault offset: 0x000000000000dd72
Faulting process id: 0xf48
Faulting application start time: 0x01d6ec0c7f8fa634
Faulting application path: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Faulting module path: C:\Windows\System32\ucrtbase.dll
Report Id: 575cd0ac-e996-49a0-8e15-486480b7396d
Faulting package full name:
Faulting package-relative application ID:
Error: (02/17/2021 02:37:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.19041.1, time stamp: 0x7f0c4c00
Faulting module name: KERNELBASE.dll, version: 10.0.19041.207, time stamp: 0x746c1866
Exception code: 0xc0000409
Fault offset: 0x000000000010b37c
Faulting process id: 0xd38
Faulting application start time: 0x01d6ec0bdf61656d
Faulting application path: C:\Windows\System32\svchost.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: bbc57b8d-899b-4ea8-a9d7-691ad1b97031
Faulting package full name:
Faulting package-relative application ID:
Error: (02/17/2021 02:12:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AVGBrowser.exe, version: 88.0.7977.152, time stamp: 0x601d8aa8
Faulting module name: KERNELBASE.dll, version: 10.0.19041.207, time stamp: 0x746c1866
Exception code: 0xe0000008
Fault offset: 0x0000000000023e49
Faulting process id: 0x26f8
Faulting application start time: 0x01d7055f6d6eee46
Faulting application path: C:\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 3b4f7e12-0c13-4d6d-b863-04ec472dd5ca
Faulting package full name:
Faulting package-relative application ID:
Error: (02/16/2021 08:22:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program HiddenCityUWP.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 1824
Start Time: 01d704c9df0db221
Termination Time: 4294967295
Application Path: C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6\HiddenCityUWP.exe
Report Id: 488aea13-736f-4746-93d9-ba2ed7a6fd52
Faulting package full name: 828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6
Faulting package-relative application ID: App
Hang type: Quiesce
Error: (02/15/2021 07:37:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program HiddenCityUWP.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 110
Start Time: 01d70392e972d1f4
Termination Time: 4294967295
Application Path: C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6\HiddenCityUWP.exe
Report Id: 85f73dca-eff8-463d-8722-6e4bf8541266
Faulting package full name: 828B5831.HiddenCityMysteryofShadows_1.39.3903.0_x86__ytsefhwckbdv6
Faulting package-relative application ID: App
Hang type: Quiesce
System errors:
=============
Error: (02/17/2021 07:24:32 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:24:27 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:24:22 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:24:14 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:24:07 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:23:55 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:23:49 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/17/2021 07:23:41 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Windows Defender:
===============
Date: 2021-02-17 15:18:35
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Full Scan
Date: 2021-02-17 15:09:02
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-02-17 15:02:31
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Full Scan
Date: 2021-02-17 15:02:31
Description:
Microsoft Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: Backdoor:Win32/Bladabindi!ml
ID: 2147748148
Severity: Severe
Category: Backdoor
Path: file:_C:\Users\User\Downloads\210125-diehl-l.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: User
Process Name: Unknown
Security intelligence Version: AV: 1.331.1187.0, AS: 1.331.1187.0, NIS: 1.331.1187.0
Engine Version: AM: 1.1.17800.5, NIS: 1.1.17800.5
Date: 2021-02-16 08:35:37
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===============
Date: 2021-02-17 20:11:44
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\AVG\Browser\Application\AVGBrowser.exe) attempted to load \Device\HarddiskVolume3\Program Files\Avast Software\Avast\aswhook.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: Dell Inc. A07 11/12/2013
Motherboard: Dell Inc. 0845MX
Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 64%
Total physical RAM: 8072.96 MB
Available physical RAM: 2849.66 MB
Total Virtual: 32648.96 MB
Available Virtual: 26968.26 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:237.87 GB) (Free:166.39 GB) NTFS
Drive e: (Sims2Deluxe) (CDROM) (Total:4.02 GB) (Free:0 GB) UDF
\\?\Volume{2abed1a5-0b0c-41be-8f1e-36fa3605a5bd}\ () (Fixed) (Total:0.49 GB) (Free:0.08 GB) NTFS
\\?\Volume{3726c5cd-416f-42c7-bf82-c61fd9444364}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 5C68B11D)
Partition: GPT.
==================== End of Addition.txt =======================
ok. i think this is correct when i ran the microsoft useless scan, it said i had a Backdoor: Win32/Bladabindi! which was severe and it said it took care of it. then it said i had a LOW something called Win32/Wacapew.C!ml but it never said that it took care of it. i hate microsoft. no one on this planet in this solarsystem part of this galaxy within this universe hates microsoft as much as i do and i don't trust anything they do, they have taken away my control of MY computer, it's not their freakin' computer, it's MINE, i paid for it, they manufactured it because no one makes computers anymore but Apple and Microsoft and who can afford an Apple? not this old fart living on a strict fixed income…. whatever, i'm ranting now. i can't help it. but because i don't trust a thing microsoft says, I then went and downloaded extra protection with AVAST and paid for $24.99 for extra protection and they said they needed my email to send the license key, but when i checked my email the protection key wasn't there, so now i'm thinking whoever infected my computer set up fake websites like the AVAST and they now have my credit card information. the avast download wasn't done after THREE HOURS. yes. i said THREE in capital letters, so i ended it thinking it was fake, no scan takes 3 freakin' hours.